[Bug 295270] www/nginx: Update to 1.30.1 to fix security issues

From: <bugzilla-noreply_at_freebsd.org>
Date: Wed, 13 May 2026 18:44:05 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295270

            Bug ID: 295270
           Summary: www/nginx: Update to 1.30.1 to fix security issues
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: joneum@FreeBSD.org
          Reporter: chris@cretaforce.gr
             Flags: maintainer-feedback?(joneum@FreeBSD.org)
          Assignee: joneum@FreeBSD.org

nginx-1.30.1 stable and nginx-1.31.0 mainline versions have been released, with
fixes for HTTP/2 request injection vulnerability in the ngx_http_proxy_module
(CVE-2026-42926), buffer overflow vulnerability in the ngx_http_rewrite_module
(CVE-2026-42945), buffer overread vulnerabilities in the ngx_http_scgi_module
and ngx_http_uwsgi_module (CVE-2026-42946), buffer overread vulnerability in
the ngx_http_charset_module (CVE-2026-42934), address spoofing vulnerability in
HTTP/3 (CVE-2026-40460), and use-after-free vulnerability in OCSP requests to
resolver (CVE-2026-40701). Additionally, nginx-1.31.0 mainline version features
support for HTTP forward proxy.

-- 
You are receiving this mail because:
You are the assignee for the bug.